IN THE CLAIMS: 



The following listing of claims will replace all prior versions, and listings, of 
claims in the application. 

1. (currently amended) A portable storage device containing network 
identification information for a processing unit , the processing unit being that is 
connectable to a data communications network and includ e s including a device reader fer 
r e ading configured to read the portable storage device, the portable storage device 
comprisingi 

storage , the storage configured to store a network identity for the processing unit 
and at least one encryption key; and 

an access controller, th e storag e holding a n e twork id e ntity for th e processing unit 
and at l e ast on e encryption k e y, and the access controller being operable to control access 
to the storage by implementing key-key encryption. 

2. (original) The portable storage device of claim 1, comprising at least one secure 
storage portion accessible only under the control of the access controller. 

3. (original) The portable storage device of claim 2, wherein said at least one 
encryption key is held in said secure storage portion. 

4. (original) The portable storage device of claim 2, wherein at least one network 
security encryption key is held in said secure storage portion. 

5. (original) The portable storage device of claim 2, wherein a file is configured in 
said secure storage portion. 

6. (original) The portable storage device of claim 2, wherein one or more files 
containing information are configured in respective secure storage portions. 
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7. (original) The portable storage device of claim 2, wherein the access controller 
is operable to perform key-key verification of a request encrypted by a request key 
supplied from the processing unit and, in response to the request key verifying correctly, 
to return to the processing unit an access key derived from said at least one encryption 
key to permit access to the secure storage portion. 

8. (original) The portable storage device of claim 7, wherein the access controller 
is subsequently operable to respond to a command from the processing unit that is 
encrypted using the access key to access the secure storage portion. 

9. (original) The portable storage device of claim 2, wherein the storage in the 
portable storage device comprises random access memory, the secure storage comprising 
a part of the random access memory. 

10. (original) The portable storage device of claim 1, wherein the access 
controller is a programmed microcontroller. 

11. (original) The portable storage device of claim 1, wherein the portable storage 
device is a smart card. 

12. (original) The processing unit of claim 1, wherein the network identity 
comprises a MAC address. 

13. (currently amended) A processing unit connectable to a data communications 
network, the processing unit having comprising: 

a device reader for a portable storage device , the portable storage device that 
includ e s comprising storage and an access controller, the storage holding a network 
identity for the processing unit and at least one encryption key, and the access controller 
controlling access to the storage by implementing key-key encryption, the processing unit 
being operable to access a secure portion of the storage of the portable storage device by 
supplying a key-encrypted request to the access controller, and, in response to receipt of 
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an access key from the access controller, being operable to send an encrypted command 
to access the content of the storage of the portable storage device. 

14. (original) The processing unit of claim 13, wherein, in response to the return 
of an access key, the processing unit is operable to use the access key to encrypt a 
command for access to a secure storage in the portable storage device. 

15. (original) The processing unit of claim 13, wherein the portable storage device 
is a smart card, the access controller is a microcontroller and the device reader is a smart 
card reader. 

16. (original) The processing unit of claim 13, wherein the network identity 
comprises a MAC address. 

17. (original) The processing unit of claim 13, comprising a service processor, the 
service processor being programmed to control reading of the portable storage device. 

18. (original) The processing unit of claim 17, wherein the service processor is a 
microcontroller. 

19. (original) The processing unit of claim 13, wherein the processing unit is a 
computer server. 

20. (original) The processing unit of claim 13, wherein the processing unit is a 
rack mountable computer server. 

21. (currently amended) A computer-readable control program for a processing 
unit connectable to a data communications network, the processing unit having 
comprising a device reader for a portable storage device that includes storage and an 
access controller, the storage holding a network identity for the processing unit and at 
least one encryption key, and the access controller controlling access to the storage by 
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implementing key-key encryption, the control program being op e rabl e executable to 
implement: 

acc e s s accessing a secure portion of the storage of the portable storage device by 
supplying a key-encrypted request to the access controller[[,]]; and[[,]] 

in response to receipt of an access key from the access controller, b e ing op e rabl e 
to s e nd sending an encrypted command to access the content of the storage of the 
portable storage device. 

22. (currently amended) The computer-readable control program of claim 21, 
wherein, in response to the return of an access key, the control program is op e rabl e 
executable to implement: 

use using the access key to encrypt a command for access to secure storage in the 
portable storage device. 

23. (currently amended) The computer-readable control program of claim 21, 
wherein the portable storage device is a smart card, wherein the access controller is a 
microcontroller and wherein the device reader is a smart card reader. 

24. (currently amended) The computer-readable control program of claim 21, 
wherein the network identity comprises a MAC address. 

25. (currently amended) The computer-readable control program of claim 21, 
comprising wherein a service processo r, th e s e rvic e processor b e ing programm e d is 
configured to control reading of the portable storage device. 

26. (currently amended) The computer-readable control program of claim 21 a 
wherein the computer-readable control program is stored on a carrier medium. 

27. (currently amended) The computer-readable control program of claim 21, 
wherein the processing unit comprises a service processor, the control program 
controlling operation of the service processor. 
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28. (currently amended) The computer-readable control program of claim 27, 
wherein the service processor is a microcontroller. 

29. (previously presented) A microcontroller connectable to a data 
communications network, the microcontroller comprising: 

a device reader for a portable storage device that includes storage and an access 
controller, the storage holding a network identity for the microcontroller and at least one 
encryption key, and the access controller controlling access to the storage by 
implementing key-key encryption; and 

a control program being operable to access a secure portion of the storage of the 
portable storage device by supplying a key-encrypted request to the access controller, 
and, in response to receipt of an access key from the access controller, being operable to 
send an encrypted command to access the content of the storage of the portable storage 
device. 

30. (currently amended) A server computer comprising: 

a device reader for r e ading configured to read a portable storage device; and 
a microcontroller, the microcontroller being operable as a service processor and 
connected to read the content of storage mounted in the portable storage device, the 
microcontroller comprising a control program for a processing unit connectable to a data 
communications network, the processing unit having a device reader for the portable 
storage device that includes storage and an access controller, the storage holding a 
network identity for the processing unit and at least one encryption key, and the access 
controller controlling access to the storage by implementing key-key encryption, the 
control program being operable to access a secure portion of the storage of the portable 
storage device by supplying a key-encrypted request to the access controller, and, in 
response to receipt of an access key from the access controller, being operable to send an 
encrypted command to access the content of the storage of the portable storage device. 
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31. (currently amended) A method for securing encryption keys for use in a 
processing unit connectable to a data communications network, the method comprising: 

providing a portable storage device for a processing unit , wherein the processing 
unit that is connectable to the data communications network , wherein the processing unit 
and includ e s comprises a device reader for r e ading configured to read the portable 
storage device, which and wherein the portable storage device comprises storage and an 
access controller; 

providing in the storage a network identity for the processing unit and at least one 
encryption key; and 

implementing key-key encryption in the access controller for controlling access to 
the storage. 

32. (original) The method of claim 31, comprising defining at least part of the 
storage in the portable storage device as secure storage accessible only under the control 
of the access controller. 

33. (original) The method of claim 32, comprising storing said at least one 
encryption key in said secure storage. 

34. (original) The method of claim 32, comprising storing at least one network 
security encryption key in said secure storage. 

35. (original) The method of claim 31, comprising: the processing unit supplying 
a key-encrypted request to the access controller; the access controller providing key-key 
verification of the request key supplied from the processing unit; and in response to the 
key-encrypted request verifying correctly; returning to the processing unit an access key 
to permit access to the secure storage; the processing unit encrypting a command using 
the access key to access the secure storage; and the access controller responding to the 
first command to access the first storage. 
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36. (original) The method of claim 31, wherein the network identity comprises a 
MAC address. 
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